Class DelegatingPasswordEncoder

java.lang.Object
com.codename1.backend.security.crypto.DelegatingPasswordEncoder
All Implemented Interfaces:
PasswordEncoder

public class DelegatingPasswordEncoder extends Object implements PasswordEncoder

Reads which scheme a stored password was made with from the {id} in front of it, so one user store can hold passwords of several ages:

{pbkdf2-sha256}pbkdf2$210000$3q2-7w$kZ...
{bcrypt}$2a$10$dXJ3SW6G7P50lGmMkkmwe.20cQQubK3.HZWzG3YB1tlRy.fqvM/BG
{noop}password

New passwords are encoded with the scheme named at construction. A stored password of any other scheme reports upgradeEncoding(String), which is what makes a sign-in re-encode it.

  • Constructor Details

    • DelegatingPasswordEncoder

      public DelegatingPasswordEncoder(String idForEncode, Map<String, PasswordEncoder> idToPasswordEncoder)
      Parameters:
      idForEncode - the scheme new passwords are encoded with
      idToPasswordEncoder - every scheme a stored password may name
  • Method Details

    • setDefaultPasswordEncoderForMatches

      public void setDefaultPasswordEncoderForMatches(PasswordEncoder encoder)
      The encoder a stored password with no {id}, or one this encoder does not know, is checked with. Unless set, such a password is refused with an exception saying so: set this to the scheme of a store that predates the prefixes.
    • encode

      public String encode(CharSequence rawPassword)
      Description copied from interface: PasswordEncoder
      The password as it should be stored: salted and hashed, so encoding one password twice gives two different results.
      Specified by:
      encode in interface PasswordEncoder
    • matches

      public boolean matches(CharSequence rawPassword, String prefixEncodedPassword)
      Description copied from interface: PasswordEncoder
      Whether rawPassword is the password encodedPassword was made from.
      Specified by:
      matches in interface PasswordEncoder
    • upgradeEncoding

      public boolean upgradeEncoding(String prefixEncodedPassword)
      Description copied from interface: PasswordEncoder
      Whether encodedPassword should be encoded again for better protection: it was made by an older scheme, or with fewer rounds than this encoder uses now.
      Specified by:
      upgradeEncoding in interface PasswordEncoder